CVE-2026-41242

EUVD-2026-23678
protobufjs compiles protobuf definitions into JavaScript (JS) functions. In versions prior to 8.0.1 and 7.5.5, attackers can inject arbitrary code in the "type" fields of protobuf definitions, which will then execute during object decoding using that definition. Versions 8.0.1 and 7.5.5 patch the issue.
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 52.25%
Affected Products (NVD)
VendorProductVersion
protobufjs_projectprotobufjs
𝑥
< 7.5.5
protobufjs_projectprotobufjs
8.0.0
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
Red HatRed Hat Developer Hub 1.8
1779841586 ≤
𝑥
< *
ADP
Red HatRed Hat Developer Hub 1.9
1781187342 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift AI 2.25
1780467029 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift AI 2.25
1780467147 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift AI 3.3
1783082680 ≤
𝑥
< *
ADP
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
protobuf
bionic
not-affected
focal
not-affected
jammy
not-affected
noble
not-affected
questing
not-affected
resolute
not-affected
trusty
not-affected
xenial
not-affected